Junglewise Threat Intelligence

CVE-2026-71930: DrayTek VigorSwitch command injection in setTime function

CVE-2026-71930 · Severity: high · CVSS 7.2 · Published 2026-08-24

Technologies: DrayTek VigorSwitch PQ2200xb, DrayTek VigorSwitch PQ2121x, DrayTek VigorSwitch P2280x, DrayTek VigorSwitch PQ2300xb, DrayTek VigorSwitch G1280, DrayTek VigorSwitch P2540xs, DrayTek VigorSwitch FX2120, DrayTek VigorSwitch P2282x, DrayTek VigorSwitch G2121, DrayTek VigorSwitch P1280, DrayTek VigorSwitch P1282, DrayTek VigorSwitch Q2300x, DrayTek VigorSwitch P2100, DrayTek VigorSwitch Q2200x, DrayTek VigorSwitch G2282x, DrayTek VigorSwitch P2540x, DrayTek VigorSwitch G2100, DrayTek VigorSwitch G2540xs, DrayTek VigorSwitch G2540x, DrayTek VigorSwitch G1282, DrayTek VigorSwitch P1281x, DrayTek VigorSwitch P2542xh, DrayTek VigorSwitch P2542x, DrayTek VigorSwitch P2121, DrayTek VigorSwitch Q2121x, DrayTek VigorSwitch G2542x, DrayTek VigorSwitch PX2060, DrayTek VigorSwitch G2280x. Vendors: DrayTek.

Executive brief

DrayTek VigorSwitch is a network management switch used in enterprise and service provider environments to control and monitor network traffic. A command injection vulnerability in the time-setting function allows authenticated administrators to execute arbitrary commands with root privileges on the device, potentially compromising network operations and data security.

Technical details

The vulnerability is a command injection flaw (CWE-78) in the setTime function within the mainfunction.cgi component. Insufficient input validation and filtering of the username and password fields allows an authenticated attacker to inject OS commands that are executed with root privileges. The attack vector is network-based and requires valid administrative credentials to authenticate to the web management interface. A successful exploit enables arbitrary code execution on the affected appliance, giving an attacker full control over the switch. Patches are available in the fixed firmware versions listed by DrayTek for each affected model.

Affected products

  • DrayTek VigorSwitch G2540xs before 3.9.10
  • DrayTek VigorSwitch P2540xs before 3.9.10
  • DrayTek VigorSwitch FX2120 before 3.9.10
  • DrayTek VigorSwitch G2282x before 2.10.6
  • DrayTek VigorSwitch P2282x before 2.10.6
  • DrayTek VigorSwitch Q2300x before 2.10.7
  • DrayTek VigorSwitch PQ2300xb before 2.10.7
  • DrayTek VigorSwitch G2542x before 3.10.6
  • DrayTek VigorSwitch P2542x before 3.10.6
  • DrayTek VigorSwitch P2542xh before 3.10.6
  • DrayTek VigorSwitch PX2060 before 2.9.10
  • DrayTek VigorSwitch G1280 before 2.9.10
  • DrayTek VigorSwitch P1280 before 2.9.10
  • DrayTek VigorSwitch P1281x before 2.9.10
  • DrayTek VigorSwitch G1282 before 2.9.10
  • DrayTek VigorSwitch P1282 before 2.9.10
  • DrayTek VigorSwitch G2121 before 2.9.10
  • DrayTek VigorSwitch P2121 before 2.9.10
  • DrayTek VigorSwitch PQ2121x before 2.9.10
  • DrayTek VigorSwitch Q2121x before 2.9.10
  • DrayTek VigorSwitch G2280x before 2.9.10
  • DrayTek VigorSwitch P2280x before 2.9.10
  • DrayTek VigorSwitch Q2200x before 2.9.10
  • DrayTek VigorSwitch PQ2200xb before 2.9.10
  • DrayTek VigorSwitch G2100 before 2.9.10
  • DrayTek VigorSwitch P2100 before 2.9.10
  • DrayTek VigorSwitch G2540x before 2.9.10
  • DrayTek VigorSwitch P2540x before 2.9.10

Timeline

  • 2026-08-24: disclosed

References

Related threats